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Top Stories 

• A Canadian National Railway Co., train struck another freight train in Slinger, Wisconsin, 
July 20 derailing 3 engines and 10 railcars and spilling about 5,000 gallons of diesel fuel, 
leading to the evacuation of around 100 nearby residents. - Associated Press (See item 7 ) 

• At least one person died and hundreds of homes were destroyed in 1 14 separate wildfires in 
several counties across eastern Washington that burned hundreds of thousands of acres. - 
Wall Street Journal (See item 18 ) 

• The sheetrock ceiling of one of five housing units at the Diboll Correction Center in 
Lufkin, Texas, collapsed July 19, leaving 19 inmates injured. - CNN (See item 21 ) 

• The Industrial Control Systems Cyber Emergency Response Team (ICS-CERT) stated July 
17 that six Siemens industrial control products used in several industries contained 
vulnerabilities in their OpenSSL implementation, with four products currently unpatched. - 
Help Net Security (See item 23) 
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Energy Sector 



See items 7 and 23 
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Chemical Industry Sector 

See item 23 
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Nuclear Reactors, Materials, and Waste Sector 

1. July 18, York Daily Record - (Pennsylvania) TMI safety system fixed after four days 
offline. A high pressure water injection system that serves as an emergency safety 
system at the Three Mile Island nuclear power plant in Pennsylvania was offline for 
over 4 days between July 10 and July 15 after the operators of the plant found a water 
leak. A second safety system was operational during the outage and workers were able 
to repair the system without shutting down the reactor after the U.S. Nuclear 
Regulatory Commission granted an extension of the normal 72 hour repair window. 
Source: http://www.ydr.com/business/ci 26 175925/tmi-safety-system- fixed-after- four- 
days-offline 
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Critical Manufacturing Sector 

2. July 19, Reuters - (National) GM says it has no fix yet for some recalled Cadillacs 
with switch issue. General Motors stated July 19 that it ordered Cadillac dealerships to 
stop sales of a total of 554,000 model year 2003-2014 CTS and 2004-2006 SRX 
vehicles due to the company still awaiting a fix for an ignition system issue that could 
allow keys to move out of position, causing a loss of power steering and airbag 
deployment. 

Source: http://www.reuters.com/article/2014/07/19/us-gm-recall-cadillac- 
idUSKBN0FQ0WP20140719 

3. July 18, Associated Press - (National) Kia recalls nearly 52,000 Souls to fix steering. 
Kia announced a recall of around 52,000 model year 2014 Soul vehicles due to the 
potential for a steering assembly pinion gear plug to loosen and cause the gear to 
separate, leading to a loss of steering. 

Source: http://wavv.com/2014/07/18/kia-recalls-nearlv-52000-souls-to-fix-steering/ 

4. July 17, Bloomberg News - (International) Tesla Model S hacked in Chinese security 
contest. Researchers with Qihoo 360 Technology Co., reported identifying security 
vulnerabilities in the Tesla Model S vehicle that could allow an attacker to remotely 
operate the door locks, horn, skylight, and headlights of the vehicle while in motion. 
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Tesla Motors stated that the company will investigate and address any issues identified 
by Qihoo 360 Technology or others during the SyScan +360 conference. 

Source: http://www.chicagotribune.com/classified/automotive/chi-tesla-rnodel-s- 
hacked,0,7108232.story 



For another story, see item 23 
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Defense Industrial Base Sector 

Nothing to report 
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Financial Services Sector 

5. July 21, The Register - (International) Secondhand Point-o-Sale terminal was 

horrific security midden. A researcher with HP found that a second-hand Aloha point- 
of-sale (PoS) terminal purchased from eBay still held a database of employee names, 
Social Security numbers, and addresses, as well as default passwords that could be used 
by an attacker if the previous owners did not change passwords in new equipment. 
Source: 

http://www.theregister.co.uk/2014/07/21/ebayed point of sale terminal leak peril/ 
For another story, see item 25 
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Transportation Systems Sector 

6. July 21, Associated Press - (Arizona) 6 die in 2 plane crashes in northern Arizona. 
Six people were killed in two separate plane crashes in northern Arizona July 20. 
Authorities are investigating the cause of both crashes after one plane went down near 
Sedona and the second plane crashed in Mohave County. 

Source: http://news.msn.com/us/6-die-in-2-plane-crashes-in-northern-arizona 

7. July 21, Associated Press - (Wisconsin) Wisconsin train crash injures 2 people, 
spills oil. A Canadian National Railway Co., train struck another freight train in 
Slinger, Wisconsin, July 20 derailing 3 engines and 10 railcars and spilling about 5,000 
gallons of diesel fuel. Two crew members were injured and around 100 residents were 
evacuated for 5 hours as a precaution. 

Source: http://news.msn.com/us/wisconsin-train-crash-iniures-2-people-spills-oil 

8. July 20, Harrisburg Patriot-News - (Pennsylvania) 10 coal cars derail, block Norfolk 
Southern line near Williamsport. A railroad track in Lycoming County was closed 
until further notice after 10 cars on a Norfolk Southern freight train derailed July 20 
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causing 4 of them to flip onto their side and spill loads of coal. The train originated 
from Lock Haven and was headed to PPL’s Montour Power Plant near 
Washingtonville. 

Source: http://www.pennlive.com/midstate/index.ssf/2014/07/10 coal cars derail bloc 
king n.html 

9. July 18, KWU 5 Henderson - (National) Allegiant computer system restored after 
outage Friday. Allegiant Air suffered an outage that lasted more than 7 hours July 18 
causing at least 26 flights to be cancelled or rescheduled. The airline restored its 
computer system after experiencing the technical glitch. 

Source: http://www.fox5vegas.com/storv/26053314/allegiant-computer-system- 
restored-after-outage-friday 
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Food and Agriculture Sector 

10. July 18, Texas Department of Agriculture - (Texas) Citrus greening quarantine 
issued for Harris County. The Texas Department of Agriculture expanded a citrus 
greening quarantine in south Texas to include Harris County, which goes into effect 
July 15 and restricts the movement of citrus trees, orange jasmine, and curry plants in 
an effort to slow the spread of the disease which causes trees to produce smaller fruit 
that drops to the ground prematurely, and results in the trees dying.. 

Source: http://www.vourhoustonnews.com/deer park/news/citrus-greening-quarantine- 
issued-for-harris-county/article 727aed61-81ec-5643-ac22-33dll3a38263.html 

11. July 20, Philadelphia Inquirer - (New Jersey) Fire closes Mount Laurel Wegmans 
store. Officials are investigating the cause of an electrical fire that broke out July 20 
inside a refrigerated display case in the produce department of a Wegmans grocery 
store in Mount Laurel. The store is expected to reopen by July 23 after store employees 
have completed cleaning the damage and discarding all affected food and products. 
Source: 

http://www.philly.com/phillv/news/new jersey/20140721 Fire closes Mount Laurel 
Wegmans store.html 

12. July 20, U.S. Food and Drug Administration - (National) Wegmans issues voluntary 
recall of bakery products that may contain fresh peaches, nectarines and plums 
supplied by Wawona Packing Company. Wegmans Food Markets, Inc., voluntarily 
issued a recall for several in-store baked desserts that may contain fresh peaches, 
nectarines, and/or plums that were supplied by Wawona Packing Company and are 
possibly contaminated with Listeria monocytogenes. No illnesses have been reported to 
Wegmans or Wawona in association with the recall. 

Source: http://www.fda.gov/Safety/Recalls/ucm405956.htm 

13. July 19, U.S. Food and Drug Administration - (National) Wawona Packing Co. takes 
precautionary step of voluntarily recalling fresh, whole peaches, plums, 
nectarines, and pluots because of possible health risk. The U.S. Food and Drug 
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Administration announced July 19 that Wawona Packing voluntarily issued a recall for 
certain lots of whole peaches, nectarines, plums, and pluots packed between June 1 and 
July 12 due to possible Listeria monocytogenes contamination. Wawona Packing 
notified business customers of the recall and requested the products be removed from 
commerce. 

Source: http://www.fda.gov/Safety/Recalls/ucm405943.htm 

14. July 18, U.S. Food and Drug Administration - (Massachusetts) Whole Foods Market 
Hyannis recalls Chocolate Chewies cookies due to undeclared tree nut allergen. 
Whole Foods Market issued a recall July 18 for Chocolate Chewies cookies produced 
and sold at its store in Hyannis, Massachusetts, due to undeclared walnuts, a known 
tree nut allergen. The products were sold in clear, clamshell packaging. 

Source: http ://w w w.fda. gov/S afety/Recalls/ucm405 942 .htm 

15. July 18, U.S. Department of Agriculture - (National) North Carolina firm recalls 
grilled chicken product due to misbranding and undeclared allergen. The Food 
Safety and Inspection Service announced July 18 that Charlotte -based B. Roberts 
Foods recalled about 202 pounds of Harris Teeter-branded refrigerated, grilled chicken 
products sold in 10-ounce containers due to undeclared milk. The recall was initiated 
after the company confirmed the product was mislabeled due to human error, a problem 
that was reported by a grocery store employee. 

Source: http://www.fsis.usda.gov/wps/portal/fsis/topics/recalls-and-public-health- 
alerts/recall-case-archi ve/archive/20 1 4/recall-046-20 1 4-release 



For another story, see item 23 
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Water and Wastewater Systems Sector 

16. July 20, WCJB 20 Gainesville - (Florida) Water main break causes boil water notice 
in Hampton. City of Hampton residents in Bradford County remained under a boil 
water advisory until further notice after a water main break near the railroad tracks July 
17. 

Source: http://www.wcib.com/local-news/2014/Q7/water-main-break-causes-boil- 
water-notice-hampton 

17. July 19, Bryan-College Station Eagle - (Texas) Record rainfall wreaks havoc across 
Bryan-College Station. Heavy rainfall in Bryan-College Station caused the Burton 
Creek Wastewater Treatment Plant to spill about 600,000 gallons of heavily diluted 
domestic wastewater when the plant lost power and the pumps stopped working July 
17. 

Source: http://www.theeagle.com/news/local/record-rainfall-wreaks-havoc-across- 
bryan-college-station/article 65c72ca7-9bb8-5f83-9c39-f0ea07890fl8.html 



-5 - 



For another story, see item 23 



[ Return to top ] 



Healthcare and Public Health Sector 

Nothing to report 
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Government Facilities Sector 

18. July 20, Wall Street Journal - (National) Washington state wildfires kill one, 
displace hundreds. At least one person died and hundreds of homes were destroyed in 
114 separate wildfires in several counties across eastern Washington that burned 
hundreds of thousands of acres. Fire crews worked over the weekend of July 19 to 
contain the fires while hundreds of residents were evacuated. 

Source: http ://online . wsi .com/articles/washington- state- wildfire- grows- 1 40587405 7 

19. July 20, WSB 2 Atlanta - (Georgia) Sam Nunn Atlanta Federal Center to close 
Monday. A power outage reported to be electrical in nature prompted the closure of the 
Sam Nunn Atlanta Federal Center in Georgia July 21. 

Source: http://www.wsbtv.com/news/news/local/sam-nunn-atlanta-federal-center- 
closed-monday/ngirt/ 

20. July 18, KITV 4 Honolulu - (Hawaii) Park, forest areas on Maui, Big Island close 
ahead of storm. The Hawaii Department of Land and Natural Resources announced 
July 18 that several parks and forest areas in Big Island, Maui, and Kauai will be closed 
over the weekend of July 19 as a safety precaution due to a projected tropical weather 
system that may produce heavy rains and flash floods. 

Source: http://www.kitv.com/weather/hurricanes/park-forest-areas-on-maui-big-island- 
close-ahead-of-storm/27037280 
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Emergency Services Sector 

21. July 20, CAW - (Texas) 19 injured when Texas prison roof collapses. The sheetrock 
ceiling of one of five housing units at the Diboll Correction Center in Lufkin, Texas, 
collapsed July 19, leaving 19 inmates injured. Authorities are investigating the cause of 
the roof collapse. 

Source: http://www.cnn.com/2014/07/19/us/prison-roof-collapse/index.html 

22. July 18, Los Angeles Times - (California) Ex-Arcadia cop convicted in theft of 
nearly $42,000 from police union. A former Arcadia police officer pleaded no contest 
July 18 to stealing close to $42,000 from the Arcadia Police Officers’ Association in 
Los Angeles while serving as the treasurer, and using the money for personal 
purchases. The former officer used the association’s credit card to buy personal items 
and then paid the monthly bills through the organization’s checking account. 
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Source: http://www.latimes.com/local/lanow/la-me-ln-arcadia-cop-convicted-of-theft- 
20140718-story.html 
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Information Technology Sector 

23. July 21, Help Net Security - (International) Unpatched OpenSSL holes found on 
Siemens ICSs. The Industrial Control Systems Cyber Emergency Response Team 
(ICS-CERT) stated July 17 that six Siemens industrial control products contained 
vulnerabilities in their OpenSSL implementation that could lead to man-in-the-middle 
(MitM) attacks or the crashing of Web servers. Four of the vulnerabilities remain 
unpatched and are present in industrial control products used by the manufacturing, 
chemical, energy, agriculture, and water industries and utilities. 

Source: http://www.net-security.org/secworld.php?id=17146 

24. July 19, Softpedia - (International) Kelihos trojan delivered through Askmen.com. 
Researchers with Malwarebytes reported that the online publication Askmen.com was 
compromised by attackers and used to redirect users to a malicious page serving the 
Nuclear Pack exploit kit for the purpose of infecting users with the Kelihos malware. 
The compromise was achieved by injecting malicious code into the Askmen.com 
server, and the site’s administrators were notified. 

Source: http://news.softpedia.com/news/Kelihos-Troian-Delivered-Through-Askmen- 
com-451345.shtml 

25. July 18, Help Net Security - (International) Fake Flash Player steals credit card 
information. Dr. Web researchers reported finding a new piece of Android malware 
dubbed BankBot that is disguised as Adobe Flash Player and persistently asks users for 
administrator privileges in order to display a fake credit card information form and steal 
any entered information. The malware is currently targeting users in Russia but can be 
repurposed to attack other targets. 

Source: http://www.net-securitv.org/malware news.php?id=28 12 

26. July 18, Securityweek - (International) Researchers analyze multipurpose malware 
targeting Linux/Unix Web servers. Virus Bulletin published an analysis of a recently 
discovered piece of malware that infects Linux and Unix Web servers known as 
Mayhem, which has infected around 1,400 servers. The malware relies on several 
plugins for various capabilities, including information stealing and brute-force attacks. 
Source: http://www.securitvweek.com/researchers-analvze-multipurpose-malware- 
targeting-linuxunix- web-servers 

27. July 18, Network World - (International) Cisco counterfeiter gets 37 months in 
prison, forfeits $700,000. The CEO of ConnectZone.com was sentenced for his role in 
conspiring with a Chinese company to produce counterfeit Cisco Systems network 
products and then sell them as genuine products. Four people and two companies were 
charged in the case, with two others found guilty and a Chinese co-conspirator 
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remaining at large. 

Source: http://www.networkworld.com/article/2455477/cisco-subnet/cisco- 
counterfeiter-gets-37-month-prison-forfeits-700-000.html 

28. July 18, Threalposi - (International) Critroni crypto ransomware seen using TOR 
for command and control. Security researchers found that a new piece of ransomware 
known as Critroni has been spotted in use by various attackers using the Angler exploit 
kit to infect users with it and other malware. The ransomware encrypts victims’ files 
and demands a ransom, and uses the TOR network to contact its command and control 
servers. 

Source: http://threatpost.com/critroni-crvpto-ransomware-seen-using-tor-for-command- 
and-control/ 107306 



Internet Alert Dashboard 



To report cyber infrastructure incidents or to request information, please contact US-CERT at soc@us-cert.gov or 
visit their Web site: http://www.us-cert.gov 

Information on IT information sharing and analysis can be found at the IT ISAC (Information Sharing and 
Analysis Center) Web site: http://www.it-isac.org 
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Communications Sector 

29. July 21, WNEW 99.1 FM Bowie - (Maryland; Washington, D.C.) Widespread Verizon 
service outage across D.C. - Baltimore region. Verizon experienced a 6 hour outage 
July 20 in the Baltimore and Washington, D.C. region that impacted many customers 
with Internet service, TV, and wireless service. Repairs were completed but many 
customers continued reporting issues with service. 

Source: http://washington.cbslocal.com/2014/07/21/widespread-verizon-service- 
outage-affecting-d-c-baltimore-region/ 
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Commercial Facilities Sector 

30. July 21, WSMV 4 Nashville - (Tennessee) Police: 75 lose homes to meth-related fire. 
A Tennessee couple was arrested and charged July 21 in connection with a July 19 
meth lab explosion and fire inside the Alta Loma Apartments in Madison which 
destroyed 8 units and displaced 75 residents. 

Source: http://www.wafb.com/storv/26062689/police-75-lose-homes-to-meth-related- 
fire 

31. July 21, KCPQ 13 Tacoma - (Washington) Two alarm apartment fire in Everett 
displaces 35 residents. The Beverly Village Apartments in Everett was rendered 
uninhabitable and 35 residents were displaced July 20 due to a 2-alarm fire that started 
on the first floor of the structure and spread throughout the building. Firefighters 
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rescued several trapped residents from the structure and no injuries were reported. 
Source: http://ql3fox.com/2014/07/2Q/two-alarm-apartment-fire-in-everett-displaces- 
35-residents 



32. July 20, WCAU 10 Philadelphia - (Pennsylvania) 1 hurt, 4 displaced after utility van 
slams into building. A Bellmawr nail salon and an attached apartment unit were 
damaged July 20 when the driver of a Paradigm Mechanical utility van lost control of 
the vehicle and crashed into the building. The driver suffered minor injuries and four 
residents were displaced by the incident. 

Source: http://www.nbcphiladelphia.com/news/local/l-Hurt-4-Displaced-After-Utility- 
V an-Slams-Into-Building-267 84096 1 .html 

33. July 19, Seattle Times - (Washington) Fire destroys some 16 units in Renton 
apartments. About 16 units at the Regency Woods Apartment Homes in Renton were 
destroyed by a fire that spread across four buildings at the complex July 19, leaving 
approximately 40 residents displaced. The cause of the fire is under investigation. 
Source: 

http://seattletimes.com/html/localnews/20241 14574 rentonapartmentfirelxml.html 

34. July 18, WLF1 18 Lafayette - (Indiana) Man injured, dozens evacuated in apartment 
complex fire. About 60 residents of The Bluffs apartment complex in Lafayette were 
evacuated for 10 hours July 18 - 19 due to a fire that broke out inside a third floor unit 
of the structure. One resident was transported to an area hospital with serious injuries. 
Source: http://wlfi.com/2014/07/17/lafavette-firefighters-called-to-apartment-complex/ 

35. July 18, KMGH 7 Denver - (Colorado) Arrest in fire at Copper Terrace 
Apartments; suspect faces attempted murder, arson charges. Police arrested a 
Colorado woman July 18 suspected of igniting a June 23 fire that injured eight people 
and destroyed four units at the Copper Terrace Apartments complex in Centennial. 
Officials believe the suspect used an accelerant to start a fire in Building G’s stairwell 
which quickly spread and trapped several residents inside the structure. 

Source: http://www.thedenverchannel.com/news/front-range/centennial/arrest-in-fire- 
at-copper-terrace-apartments-naomi-almodovar-faces-attempted-murder-arson-charges 
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Dams Sector 

Nothing to report 
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About the reports - The DHS Daily Open Source Infrastructure Report is a daily [Monday through Friday] 
summary of open-source published information concerning significant critical infrastructure issues. The DHS Daily 
Open Source Infrastructure Report is archived for 10 days on the Department of Homeland Security Web site: 
http://www.dhs.gov/IPDailyReport 

Contact Information 

Content and Suggestions: Send mail to cikr.productfeedback@hq.dhs.gov or contact the DHS 

Daily Report Team at (703) 942-8590 

Subscribe to the Distribution List: Visit the DHS Daily Open Source Infrastructure Report and follow 

instructions to Get e-mail updates when this information changes . 

Removal from Distribution List: Send mail to support @ govdelivery.com . 



Contact DHS 

To report physical infrastructure incidents or to request information, please contact the National Infrastructure 
Coordinating Center at nicc@hq.dhs.gov or (202) 282-9201. 

To report cyber infrastructure incidents or to request information, please contact US -CERT at soc@us-cert.gov or visit 
their Web page at www.us-cert.gov . 

Department of Homeland Security Disclaimer 

The DHS Daily Open Source Infrastructure Report is a non-commercial publication intended to educate and inform 
personnel engaged in infrastructure protection. Further reproduction or redistribution is subject to original copyright 
restrictions. DHS provides no warranty of ownership of the copyright, or accuracy with respect to the original source 
material. 



- 10 - 




